Complete Gallery Manager [complete-gallery-manager] < 3.3.4 (closed)
unknown
[en] Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[...
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Sep 30, 2013
CVE-2013-5962 on NVD →
Complete Gallery Manager [complete-gallery-manager] < 3.3.4
unknown
Complete Gallery Manager is prone to an arbitrary file upload vulnerability that is located in the /plugins/complete-gallery-manager/frames/ path when processing to upload via the upload-images.php
file own malicious context or webshells.The vulnerability allows the attackers to upload files via POST method with mul...
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Sep 18, 2013
Complete Gallery Manager <= 3.3.3 - Arbitrary File Upload
critical
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month...
- CVSS:
- 9.8
- Affected:
- up to 3.3.4
- Fixed in:
- 3.3.4
- Disclosed:
- Sep 17, 2013
CVE-2013-5962 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database